Public agent API / v1
Authentication
REST and MCP accept the same Clerk OAuth 2.1 access tokens. QuiltLab does not issue API keys in v1.
Discover and authorize
- Read llms.txt or the API catalog to find the published surface.
- Fetch protected-resource metadata. Follow the returned authorization server to its OAuth authorization-server metadata.
- Use your OAuth client to complete authorization with Clerk and exchange the authorization code at the discovered
token_endpoint. Use the discovered resource identifier for the connection. - Send the resulting access token as a bearer token on REST requests or let your MCP client manage the connection.
QuiltLab's authorization-server metadata proxy is GET-only. It is not a token endpoint. Read endpoint URLs from discovery rather than constructing them.
Authorization: Bearer <access_token>Probe GET /api/v1/auth/me before calling private design operations. It returns success: true and data containing authenticated and the caller's userId; it does not return email or collaborator identities.
Public and private operations
Fabric catalog searches and supply guides allow anonymous reads. Your projects and saved designs require authentication. A supplied invalid or expired bearer token returns HTTP 401, even if a valid browser session is present.
A 401 includes WWW-Authenticate with a resource_metadata URL. Follow it to reauthorize; see Errors for the response shape.
Browser sessions and request origins
Same-origin browser clients can use their Clerk session cookie instead of a bearer token. Cookie-authenticated writes run the CSRF origin check: supplied Origin and Referer origins must be allowed. This API does not require a separate CSRF-token header.
GET and HEAD requests do not run the write check. OAuth bearer writes skip this cookie-specific check. Use OAuth for external integrations; do not copy browser cookies into agents.